# Siemens Siveillance Video RCE via OS Command Injection

Published: 2026-08-13 · Severity: routine · Sectors: manufacturing, telecommunications
Canonical: https://vorant.io/reports/bdd70f58-4232-5954-8c80-81939ece9a65/siemens-siveillance-video-rce-via-os-command-injection

> An OS command injection flaw in Siemens Siveillance Video Management Server API lets users with edit permissions run arbitrary code; patches are available.

CISA republished a Siemens ProductCERT advisory (SSA-825228) covering CVE-2026-3014, an OS command injection vulnerability (CWE-78) in the Management Server API of Siveillance Video, Siemens' rebrand of Milestone XProtect. The flaw allows a user who already holds edit permissions on the Management Server to execute arbitrary code in the context of the Management Server Service, effectively enabling privilege escalation to remote code execution for an already-authenticated, privileged operator.

Affected versions span Siveillance Video V2023 R3 (<23.3.27), V2024 R1 (<24.1.16), and V2025 (<25.1.15). Milestone has released fixed builds and cumulative hotfixes for each branch, and Siemens directs customers to apply HotfixRev27, HotfixRev16, or HotfixRev15 respectively depending on their deployed version. The vulnerability was reported by Milestone PSIRT and there is no evidence of exploitation in the wild; this is a vendor-issued patch advisory rather than an active-exploitation report.

Affected sectors per the advisory include Critical Manufacturing, Communications, and Commercial Facilities, with worldwide deployment. CISA's standard ICS mitigations apply: minimize network exposure of control system devices, isolate them behind firewalls from business networks, and use secure remote access methods such as VPNs where necessary.

## Mentioned in this report

- Vulnerabilities: CVE-2026-3014

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-10

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/bdd70f58-4232-5954-8c80-81939ece9a65/siemens-siveillance-video-rce-via-os-command-injection.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
